{"id":33301,"date":"2019-10-31T21:51:51","date_gmt":"2019-10-31T18:51:51","guid":{"rendered":"https:\/\/prohoster.info\/blog\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root\/"},"modified":"2019-10-31T21:51:51","modified_gmt":"2019-10-31T18:51:51","slug":"docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root","title":{"rendered":"Las im\u00e1genes de Docker de Alpine se entregaron con una contrase\u00f1a vac\u00eda para el usuario root","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Investigadores de seguridad de Cisco <noindex><a rel=\"nofollow\" href=\"https:\/\/talosintelligence.com\/vulnerability_reports\/TALOS-2019-0782\">revelaron<\/a><\/noindex> informaci\u00f3n sobre la vulnerabilidad (CVE-2019-5021) en <noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/_\/alpine\">las construcciones<\/a><\/noindex> del distribuci\u00f3n de Alpine para el sistema de aislamiento de contenedores Docker. La esencia del problema identificado es que se estableci\u00f3 una contrase\u00f1a vac\u00eda por defecto para el usuario root sin bloquear el acceso directo como root. Cabe recordar que Alpine se utiliza para formar las im\u00e1genes oficiales del proyecto Docker (anteriormente, las construcciones oficiales estaban basadas en Ubuntu, pero luego fueron <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=43828\">convertidas<\/a><\/noindex> a Alpine).<\/p>\n<p>El problema se manifiesta a partir de la construcci\u00f3n Alpine Docker 3.3 y fue causado por un cambio regresivo a\u00f1adido en 2015 (antes de la versi\u00f3n 3.3, en \/etc\/shadow se utilizaba la l\u00ednea \u00abroot:!::0:::::\u00bb, y despu\u00e9s, debido a la eliminaci\u00f3n del uso del flag \u00ab-d\u00bb, se comenz\u00f3 a a\u00f1adir la l\u00ednea \u00abroot:::0:::::\u00bb). El problema fue detectado inicialmente y <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gliderlabs\/docker-alpine\/commit\/8b9abf92b9960b7153b93268580099f34ef20f69\">corregido<\/a><\/noindex> en noviembre de 2015, pero en diciembre volvi\u00f3 a surgir por error <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gliderlabs\/docker-alpine\/commit\/ab4337c595383afa0f792ff01d3f99bc6667c3a8#diff-fc53135be554a2608c163978ed2f710b\">en los archivos de construcci\u00f3n de la rama experimental, y luego se traslad\u00f3 a las construcciones estables.<\/a><\/noindex> La informaci\u00f3n sobre la vulnerabilidad indica que el problema se manifiesta tambi\u00e9n en la \u00faltima rama de Alpine Docker 3.9. Los desarrolladores de Alpine lanzaron en marzo<\/p>\n<p>una correcci\u00f3n y la vulnerabilidad <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/docker-library\/official-images\/pull\/5516\">no se manifiesta<\/a><\/noindex> desde las construcciones 3.9.2, 3.8.4, 3.7.3 y 3.6.5, pero persiste en las antiguas ramas 3.4.x y 3.5.x, cuyo soporte ya ha terminado. Adem\u00e1s, los desarrolladores afirman que el vector de ataque est\u00e1 muy limitado y requiere que el atacante tenga acceso a la misma infraestructura. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/alpinelinux\/docker-alpine\/issues\/13\">La cuota de la plataforma Pie en el mercado de Android super\u00f3 el 10%<\/a><\/noindex> El lanzamiento del sistema operativo Trident 19.04 del proyecto TrueOS y el escritorio Lumina 1.5.0<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50654\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-5021) \u0432 \u0441\u0431\u043e\u0440\u043a\u0430\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Alpine \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043d\u043e\u0439 \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 Docker. \u0421\u0443\u0442\u044c \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u0431\u044b\u043b \u0437\u0430\u0434\u0430\u043d \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043f\u0443\u0441\u0442\u043e\u0439 \u043f\u0430\u0440\u043e\u043b\u044c \u0431\u0435\u0437 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u043f\u0440\u044f\u043c\u043e\u0433\u043e \u0432\u0445\u043e\u0434\u0430 \u043f\u043e\u0434 root. \u041d\u0430\u043f\u043e\u043c\u043d\u0438\u043c, \u0447\u0442\u043e Alpine \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 \u043e\u0442 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Docker (\u0440\u0430\u043d\u044c\u0448\u0435 \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u0431\u043e\u0440\u043a\u0438 \u043e\u0441\u043d\u043e\u0432\u044b\u0432\u0430\u043b\u0438\u0441\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-33301","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-5021) \u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Docker-\u043e\u0431\u0440\u0430\u0437\u044b Alpine \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u043b\u0438\u0441\u044c \u0441 \u043f\u0443\u0441\u0442\u044b\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-5021) \u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:51:51+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:51:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Las im\u00e1genes de Docker de Alpine se entregaron con una contrase\u00f1a vac\u00eda para el usuario root | ProHoster","description":"Investigadores de seguridad de Cisco revelaron informaci\u00f3n sobre la vulnerabilidad (CVE-2019-5021) en.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Docker-\u043e\u0431\u0440\u0430\u0437\u044b Alpine \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u043b\u0438\u0441\u044c \u0441 \u043f\u0443\u0441\u0442\u044b\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-5021) \u0432.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:51:51+00:00","article:modified_time":"2019-10-31T18:51:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"33301","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 14:43:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:43:31","updated":"2026-01-21 14:43:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/33301","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=33301"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/33301\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=33301"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=33301"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=33301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}